VDB

CVE-2026-46483

CVE-2026-46483 PUBLISHED CVSS 3.5999999046325684 LOW

Vim is an open source, command line text editor. Prior to 9.2.0479, a command injection vulnerability exists in tar#Vimuntar() in runtime/autoload/tar.vim when decompressing .tgz archives on Unix-like systems. The function builds :!gunzip and :!gzip -d commands using shellescape(tartail) without the {special} flag, allowing a crafted archive filename to trigger Vim cmdline-special expansion and execute shell commands in the user's context. This vulnerability is fixed in 9.2.0479.

EPSS 0.02% · 4.3th percentile

Risk Scores

CVSS v3.1
3.5999999046325684
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
EPSS Score
0.02%
4.3th percentile

Affected Products

VendorProductVersions
vimvim*

Timeline

  • May 15, 2026 CVE Published
  • May 15, 2026 CVE Updated
  • May 18, 2026 EPSS Score
  • May 18, 2026 Security Advisory
  • May 19, 2026 EPSS Score
  • May 20, 2026 EPSS Score
  • May 21, 2026 EPSS Score
  • May 21, 2026 Security Advisory
  • May 21, 2026 Security Advisory
  • May 21, 2026 Security Advisory
  • May 21, 2026 Security Advisory
  • May 21, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›